Showing posts with label Meteocontrol. Show all posts
Showing posts with label Meteocontrol. Show all posts

Wednesday, May 18, 2016

ICS-CERT Updates Meteocontrol Advisory

This morning the DHS ICS-CERT published an updated advisory for control system vulnerabilities reported in the Meteocontrol WEB'log. The Advisory was originally published last week and I reported on potential problems with the advisory yesterday. Additionally, the Karn Ganeshen memo to Full Disclosure on this topic is now available.

Revised Advisory


ICS-CERT made changes to two areas of the Advisory. First they added a new paragraph to the ‘Impact’ section of the advisory. That new paragraph reads:

“Successful exploitation of these vulnerabilities can allow silent execution of unauthorized actions on the device such as modifying plant data; modifying modbus/inverter/other devices; configuration parameters; and saving modified configuration and device reboot.”

ICS-CERT also made a number of changes to the vulnerability overview section of the advisory. They changed the title and description of the first two vulnerabilities and added a third new vulnerability.

The ‘Information Exposure’ vulnerability (CVE-2016-2296) was changed to ‘Improper Access Control’ with this new description:

“All application functionality, and configuration pages, including those accessible after administrative login, can be accessed without any authentication.”

The ‘No Authentication’ vulnerability (CVE-2016-2297) was changed to ‘Command Shell Accessible’ with this new description:

“The application has a hidden/obscured access command shell-like feature that allows anyone to run a restricted set of system commands. This shell can be accessed directly without any authentication.”

Finally, ICS-CERT added a Cross-Site Request Forgery vulnerability (CVE-2016-4504).

Full Disclosure Memo


I mentioned yesterday that Karn Ganeshen had reportedly sent a memo to the Full Disclosure list explaining the deficiencies in the original Meteocontrol Advisory. Today that memo has been published on the site. In that memo, Karn has provided sample URLs that would allow access to the information on WEB’log devices without authentication.


I’m not sure if this information rises to the level of ‘exploit code’ since some additional work (I think) would have to be done to get these sample URL’s to work. In any case ICS-CERT continues in this version of the Advisory to report that: “No known public exploits specifically target these vulnerabilities.” Then again, they may not have known about the existence of this Full Disclosure memo when they revised the Advisory.

Tuesday, May 17, 2016

ICS-CERT Publishes Two Advisories

This morning the DHS ICS-CERT published two control system advisories for products from Moxa and iRZ. The Moxa advisory was previously published on the US-CERT Secure Portal. I also mention some additional vulnerability news.

Moxa Advisory


This advisory describes five vulnerabilities in the Moxa ECRG903 secure routers. The vulnerabilities were reported by Maxim Rupp. Moxa had developed a new firmware version that mitigates the vulnerabilities. There is no indication that Rupp was provided the opportunity to verify the efficacy of the fix.

The five vulnerabilities include:

• Privilege escalation - CVE-2016-0875;
• Plaintext storage of password - CVE-2016-0876;
• Memory leak - CVE-2016-0877;
• Denial of service - CVE-2016-0878; and
• Unauthenticated file download - CVE-2016-0879

ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to escalate privileges, initiate a denial-of-service condition, and execute arbitrary code.

iRZ Advisory


This advisory describes a firmware overwrite vulnerability in the iRZ RUH2 serial-to-Ethernet interface. Apparently this is a self-reported vulnerability though ICS-CERT reports that an exploit is publicly available. iRZ no longer supports this device so no mitigation measures will be forth coming.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to upload new firmware to the device.

Other Vulnerability Notes


I had an interesting TWEET directed my way this morning by Brandon Workentin. He said: “Full Disclosure has email by Meteocontrol vuln reporter saying ICS-CERT advisory ‘not complete and accurate.’ Not on FD archive yet”. ICS-CERT published that vulnerability advisory last week.

When I looked on Full Disclosure to see if that report had been published yet (it hasn’t) I was surprised to find another Moxa vulnerability report from early this month that hasn’t been reported by ICS-CERT yet. This is unusual in that Karn Ganeshen, the apparent reporter, has done numerous coordinated disclosures, so there should be an interesting story here.


BTW: Karn was also the reporter on the Meteocontrol Advisory. I’ll be watching Full Disclosure for this reported email.

Thursday, May 12, 2016

ICS-CERT Publishes Meteocontrol Advisory and Meeting Announcement

This morning the DHS ICS-CERT published a control system advisory for a WEB’log application from Meteocontrol. The also published the date for the fall meeting of the ICSJWG.

Meteocontrol Advisory


This advisory describes three vulnerabilities in the Meteocontrol WEB’log application. The vulnerabilities were reported by Karn Ganeshen. Meteocontrol has produced a new version that mitigates the vulnerability. There is no indication that Ganeshen has been provided the opportunity to verify the efficacy of the fix.

The vulnerabilities include:

• Information exposure - CVE-2016-2296;
• No authentication - CVE-2016-2297; and
• Sensitive information exposure - CVE-2016-2298.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit these vulnerabilities to run system commands or access sensitive information.

ICSJWG Fall Meeting



ICS-CERT announced that the Fall 2016 ICSJWG Meeting will be held in Ft. Lauderdale, FL on September 13-15, 2016. The ICSJWG web site will have additional information (including registration and a call for abstracts) in the near future.
 
/* Use this with templates/template-twocol.html */